Track 3 platforms and get the weekly governance digest. No credit card required.
This page describes what the document states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability may vary by jurisdiction. Methodology
This is Stripe's public disclosure list of the third-party companies and internal affiliates that process personal data on behalf of Stripe's business customers, updated December 20, 2025. The document states that Business Users operating under Stripe's Data Processing Agreement have 30 days from any page update to object in writing to a new sub-processor, and that silence within that window is treated as acceptance. The update adds several new entities including sub-processors for Japan payment integration (NETSTARS Co., Ltd.), check scanning (Jack Henry & Associates, Inc. and Mitek Systems, Inc.), stablecoin and crypto services (Horkos, Inc., Bridge Ventures, LLC, and related Bridge entities), and a new EMEA and APAC data controller (Stripe Technology Company Limited).
This document is Stripe's Sub-processor and Affiliate Disclosure List, last updated December 20, 2025, published pursuant to GDPR and other global privacy frameworks that require data processors to maintain and disclose sub-processor arrangements when processing personal data on behalf of business customers. The document states that Business Users may object in writing to the appointment of a new sub-processor within 30 days of a page update, and that failure to object within this window is deemed acceptance under the terms of Stripe's Data Processing Agreement. The document discloses a materially expanded affiliate network including newly added entities in the stablecoin and crypto space (Horkos, Inc., Bridge Ventures, LLC, Bridge Building Sp. Z.o.o., Bridge Building S.A., and Stripe Global Technology, LLC), a newly designated EMEA and APAC data controller (Stripe Technology Company Limited), and the conversion of Stripe, Inc. to Stripe, LLC effective January 3, 2026, each of which may trigger data mapping, DPA review, and regulatory notification obligations for affected Business Users. The document engages GDPR sub-processor notification requirements, India's data localization regulations (referenced for Stripe India Private Limited), and financial services regulatory frameworks in Ireland (Central Bank of Ireland), the UK (FCA), and multiple APAC and LATAM jurisdictions. Compliance teams in the EU, UK, and other jurisdictions with formal DPA structures should evaluate whether the newly listed entities, particularly those handling stablecoin and crypto-related personal data, fall within the scope of existing contractual sub-processor consent mechanisms and require updated data transfer impact assessments.
Institutional analysis available with Compliance
Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.
Get ComplianceEvery distinct legal provision identified in this document. Featured provisions appear above with analysis.
Monitoring
Stripe has updated this document before.
Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
Compliance Governance Intelligence
Need provision-level monitoring and regulatory mapping?
Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.
Get ComplianceCross-platform context
See how other platforms handle 30-Day Written Objection Right For New Sub-Processor and similar clauses.
Compare across platforms →Stripe's terms authorize fund reserves, payout withholding, and account termination. Here is what the agreement states and what business ow…
The Kickstarter-Stripe controversy reveals how payment processors, cloud providers, and AI platforms quietly shape downstream policy decisi…
Mastercard, Stripe, and Cloudflare are building payment infrastructure for autonomous AI agents. The governance layer is not keeping pace.
Governance Monitoring
Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.